Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8xf7-v5jv-237f

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

EPSS

Процентиль: 100%
0.92249
Критический

9.8 Critical

CVSS3

Дефекты

CWE-200
CWE-276

Связанные уязвимости

CVSS3: 9.8
nvd
около 13 лет назад

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

CVSS3: 9.6
fstec
около 13 лет назад

Уязвимость компонента administrator.cfc веб-интерфейса программной платформы ColdFusio, позволяющая нарушителю обойти ограничения безопасности или выполнить произвольный код

EPSS

Процентиль: 100%
0.92249
Критический

9.8 Critical

CVSS3

Дефекты

CWE-200
CWE-276